Expand description
Classic-BPF seccomp filters built directly from the data, for the local runner: no container, no libseccomp, and no root.
The program makes the same decisions as crate::seccomp_profile:
- Any architecture other than x86_64 (e.g.
int 0x80i386 calls) and any x32 syscall number returnsENOSYS. madvisereturnsEINVALunless the low 32 bits of the advice (the kernel reads anint) are a value the target kernel knows.- Syscalls the target provides are allowed; everything else, including
numbers this crate’s data does not know, returns
ENOSYS.
Installing a filter needs no privilege once the process has set
PR_SET_NO_NEW_PRIVS. Like the profiles, the filter is a testing aid and
not a security boundary.
Modules§
- install
- Installs filters in the calling thread (and what it executes).
Structs§
- Insn
- One
struct sock_filterinstruction.
Constants§
- AUDIT_
ARCH_ X86_ 64 AUDIT_ARCH_X86_64:EM_X86_64 | __AUDIT_ARCH_64BIT | __AUDIT_ARCH_LE.- MAX_
INSNS - The kernel’s
BPF_MAXINSNS. - RET_
ALLOW SECCOMP_RET_ALLOW.- RET_
ERRNO SECCOMP_RET_ERRNO; the errno goes in the low 16 bits.- SYS_
MADVISE - x86_64
madvisesyscall number. - X32_
SYSCALL_ BIT - Syscall numbers at or above this bit belong to the x32 ABI.